CVE-2025-13945: Improperly Controlled Sequential Memory Allocation in Wireshark
Published Dec 3, 2025
·Updated
HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service
Affected Software
2 affected components
Wireshark Wireshark>=4.6.0<=4.6.1
Wireshark Wireshark>=4.6.0<4.6.2
Remediation
Information
Upgrade to version 4.6.2 or above
Patch Available
Event History
Dec 3, 2025
CVE Published
via MITRE·08:04 AM
Data Sourced
via MITRE·08:04 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13945?
CVE-2025-13945 has a severity rating that indicates it can lead to denial of service in affected versions of Wireshark.
2
How do I fix CVE-2025-13945?
To fix CVE-2025-13945, users should upgrade Wireshark to version 4.6.2 or later.
3
Which versions of Wireshark are affected by CVE-2025-13945?
CVE-2025-13945 affects Wireshark versions 4.6.0 and 4.6.1.
4
What does CVE-2025-13945 affect in Wireshark?
CVE-2025-13945 affects the HTTP3 dissector, causing it to crash and lead to denial of service.
5
Is there a workaround for CVE-2025-13945?
There is no specific workaround for CVE-2025-13945; upgrading to a patched version is recommended.